Intel

AIKIDO-2026-817335

craftcms/cms is vulnerable to Authorization Bypass

Authorization BypassGHSA-6qw4-cjqw-fj72 Published Yesterday

78

High Risk

This Affects:

PHPcraftcms/cms
5.0.0 - 5.10.10
Fixed in 5.10.11
Are you affected? Scan for Free

TL;DR

Craft CMS 5.10.11 fixes ten independently reported security issues. GHSA-5mjc-jqcw-6vrp exposed aggregate metadata for restricted asset volumes; GHSA-ccpq-mw3m-wwg2 allowed inline entry saves into unauthorized sections; GHSA-5fjj-496j-2qqf allowed administrator-stored site-name XSS; GHSA-9xvf-7w97-83mv allowed unauthorized replacement or deletion of conflicting assets; GHSA-242m-9wq7-vhwq could preserve administrator status when a deactivated account was reused during public registration; GHSA-3wcr-p33w-528f bypassed GraphQL site scope in entry mutations; GHSA-2f55-h4xr-92p2 allowed unauthorized provisional-draft deletion; GHSA-5fh8-74j8-mvcp propagated draft authorization to canonical per-site deletion; GHSA-329j-cx85-8r56 allowed replacement of peer-owned asset files; and GHSA-6qw4-cjqw-fj72 allowed a non-admin user administrator to mint an administrator password-reset URL. A deployment within the vulnerable range may be exposed to one or more of these issues depending on its enabled features and permission model.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and your deployment permits control panel users, public registration with email verification disabled, or scoped GraphQL entry mutations.

Background info

craftcms/cms is vulnerable to Authorization Bypass in versions 5.0.0 - 5.10.10.

How to fix this

Upgrade the craftcms/cms library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform